Worm

Worm.Win32.Vobfus.est information

Malware Removal

The Worm.Win32.Vobfus.est is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Vobfus.est virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Worm.Win32.Vobfus.est?


File Info:

name: 3C422631126F04F1553B.mlw
path: /opt/CAPEv2/storage/binaries/888207364ec256b6d83d31bd33eb2cf15520c7e9c7016bd6cf0fa2075fa225e9
crc32: C84E6457
md5: 3c422631126f04f1553bc6d0fc31f3f1
sha1: 5490f5a199fffe7a9f843c5b74222ae55115e294
sha256: 888207364ec256b6d83d31bd33eb2cf15520c7e9c7016bd6cf0fa2075fa225e9
sha512: aacf7433e7d3f01e91ca24d496ed7c0745368a03fa1dceca8a7980fe617e04077dffa9e590eb2c859a7212b1f8fa129ff4d5ef97bbc49fbf8e500b9499c8407b
ssdeep: 1536:hnSOpXbM3bW1UENmGJUJaBurC53ArsD77UsMJHuomPnzqLcTJLO01DvqJWgP0gy8:hSOpXbXvlFz77UsMJHuoVDwfG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FDE3F93B77854785D648267525EBC3E626A378299F0B91073988733A7CB2F301E69F43
sha3_384: e35b2cb76b83ef4740556b6aa428098de1fe57f3227a4242abccb821b54dc7a681e783e9277ce15e78659fe7d338b744
ep_bytes: 685c134000e8eeffffff000058000000
timestamp: 2012-09-21 05:52:15

Version Info:

Translation: 0x0409 0x04b0
ProductName: Openvpn
FileVersion: 4.35
ProductVersion: 4.35
InternalName: sender
OriginalFilename: sender.exe

Worm.Win32.Vobfus.est also known as:

BkavW32.AIDetectMalware
AVGWin32:VB-AENV [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Barys.950
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.ct
McAfeeGenDownloader.rv
MalwarebytesVBObfus.Worm.Spreader.DDS
SangforSuspicious.Win32.Save.a
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
VirITTrojan.Win32.X-Cryptor.GDL
SymantecW32.Changeup!gen20
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VBObfus.BV
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.est
BitDefenderGen:Variant.Barys.950
NANO-AntivirusTrojan.Win32.Vobfus.coonpv
AvastWin32:VB-AENV [Trj]
TencentWorm.Win32.Vobfus.haw
EmsisoftGen:Variant.Barys.950 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLW.Autoruner1.26617
VIPREGen:Variant.Barys.950
TrendMicroWORM_VOBFUS.SM00
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3c422631126f04f1
SophosMal/SillyFDC-Y
SentinelOneStatic AI – Malicious PE
JiangminWorm/Vobfus.jqd
WebrootW32.Worm.Sm00
VaristW32/Vobfus.AQ.gen!Eldorado
AviraTR/Dropper.Gen
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.999
MicrosoftWorm:Win32/Vobfus.ID
XcitiumTrojWare.Win32.Pronny.EE@4qvpy8
ArcabitTrojan.Barys.950
ViRobotWorm.Win32.A.Vobfus.143360.C
ZoneAlarmWorm.Win32.Vobfus.est
GDataGen:Variant.Barys.950
GoogleDetected
AhnLab-V3Worm/Win32.Vobfus.R38810
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.36804.im0@a0J!nEbi
MAXmalware (ai score=80)
VBA32TScope.Trojan.VB
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM00
RisingTrojan.VB!1.99F7 (CLASSIC)
YandexTrojan.GenAsa!jFECs454SRI
IkarusWorm.Win32.Vobfus
MaxSecureTrojan.Malware.4579014.susgen
FortinetW32/VBObfus.AU!tr
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.9a748115

How to remove Worm.Win32.Vobfus.est?

Worm.Win32.Vobfus.est removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment